<!DOCTYPE html><html lang="en" data-theme="light"><head><meta charset="UTF-8"><meta http-equiv="X-UA-Compatible" content="IE=edge"><meta name="viewport" content="width=device-width,initial-scale=1"><title>Hexo | Hexo</title><meta name="author" content="John Doe"><meta name="copyright" content="John Doe"><meta name="format-detection" content="telephone=no"><meta name="theme-color" content="#ffffff"><meta name="description" content="一、基础入门—概念名词域名  什么是域名？  www.xxx.com类似的的网站。（可在万网注册）   什么是二级域名和多级域名？  www.xxx.com中www是顶级域名，xxx是二级域名；    ​                com前面的就是二级域名； ​                xxx前面的是多级域名。  域名类型对于安全有什么意义？ 以https:&#x2F;&#x2F;www.haut.edu.">
<meta property="og:type" content="article">
<meta property="og:title" content="Hexo">
<meta property="og:url" content="http://example.com/2021/07/19/%E5%B0%8F%E8%BF%AAweb%E7%AC%94%E8%AE%B0/index.html">
<meta property="og:site_name" content="Hexo">
<meta property="og:description" content="一、基础入门—概念名词域名  什么是域名？  www.xxx.com类似的的网站。（可在万网注册）   什么是二级域名和多级域名？  www.xxx.com中www是顶级域名，xxx是二级域名；    ​                com前面的就是二级域名； ​                xxx前面的是多级域名。  域名类型对于安全有什么意义？ 以https:&#x2F;&#x2F;www.haut.edu.">
<meta property="og:locale" content="en_US">
<meta property="og:image" content="https://cdn.jsdelivr.net/npm/butterfly-extsrc@1/img/default.jpg">
<meta property="article:published_time" content="2021-07-19T14:09:45.390Z">
<meta property="article:modified_time" content="2021-07-19T14:14:50.827Z">
<meta property="article:author" content="John Doe">
<meta name="twitter:card" content="summary">
<meta name="twitter:image" content="https://cdn.jsdelivr.net/npm/butterfly-extsrc@1/img/default.jpg"><link rel="shortcut icon" href="/img/favicon.png"><link rel="canonical" href="http://example.com/2021/07/19/%E5%B0%8F%E8%BF%AAweb%E7%AC%94%E8%AE%B0/"><link rel="preconnect" href="//cdn.jsdelivr.net"/><link rel="preconnect" href="//busuanzi.ibruce.info"/><link rel="stylesheet" href="/css/index.css"><link rel="stylesheet" href="https://cdn.jsdelivr.net/npm/@fortawesome/fontawesome-free/css/all.min.css" media="print" onload="this.media='all'"><script>const GLOBAL_CONFIG = { 
  root: '/',
  algolia: undefined,
  localSearch: undefined,
  translate: undefined,
  noticeOutdate: undefined,
  highlight: {"plugin":"highlighjs","highlightCopy":true,"highlightLang":true,"highlightHeightLimit":false},
  copy: {
    success: 'Copy successfully',
    error: 'Copy error',
    noSupport: 'The browser does not support'
  },
  relativeDate: {
    homepage: false,
    post: false
  },
  runtime: '',
  date_suffix: {
    just: 'Just',
    min: 'minutes ago',
    hour: 'hours ago',
    day: 'days ago',
    month: 'months ago'
  },
  copyright: undefined,
  lightbox: 'fancybox',
  Snackbar: undefined,
  source: {
    jQuery: 'https://cdn.jsdelivr.net/npm/jquery@latest/dist/jquery.min.js',
    justifiedGallery: {
      js: 'https://cdn.jsdelivr.net/npm/justifiedGallery/dist/js/jquery.justifiedGallery.min.js',
      css: 'https://cdn.jsdelivr.net/npm/justifiedGallery/dist/css/justifiedGallery.min.css'
    },
    fancybox: {
      js: 'https://cdn.jsdelivr.net/npm/@fancyapps/fancybox@latest/dist/jquery.fancybox.min.js',
      css: 'https://cdn.jsdelivr.net/npm/@fancyapps/fancybox@latest/dist/jquery.fancybox.min.css'
    }
  },
  isPhotoFigcaption: false,
  islazyload: false,
  isanchor: false
}</script><script id="config-diff">var GLOBAL_CONFIG_SITE = {
  title: 'Hexo',
  isPost: true,
  isHome: false,
  isHighlightShrink: false,
  isToc: true,
  postUpdate: '2021-07-19 22:14:50'
}</script><noscript><style type="text/css">
  #nav {
    opacity: 1
  }
  .justified-gallery img {
    opacity: 1
  }

  #recent-posts time,
  #post-meta time {
    display: inline !important
  }
</style></noscript><script>(win=>{
    win.saveToLocal = {
      set: function setWithExpiry(key, value, ttl) {
        if (ttl === 0) return
        const now = new Date()
        const expiryDay = ttl * 86400000
        const item = {
          value: value,
          expiry: now.getTime() + expiryDay,
        }
        localStorage.setItem(key, JSON.stringify(item))
      },

      get: function getWithExpiry(key) {
        const itemStr = localStorage.getItem(key)

        if (!itemStr) {
          return undefined
        }
        const item = JSON.parse(itemStr)
        const now = new Date()

        if (now.getTime() > item.expiry) {
          localStorage.removeItem(key)
          return undefined
        }
        return item.value
      }
    }
  
    win.getScript = url => new Promise((resolve, reject) => {
      const script = document.createElement('script')
      script.src = url
      script.async = true
      script.onerror = reject
      script.onload = script.onreadystatechange = function() {
        const loadState = this.readyState
        if (loadState && loadState !== 'loaded' && loadState !== 'complete') return
        script.onload = script.onreadystatechange = null
        resolve()
      }
      document.head.appendChild(script)
    })
  
      win.activateDarkMode = function () {
        document.documentElement.setAttribute('data-theme', 'dark')
        if (document.querySelector('meta[name="theme-color"]') !== null) {
          document.querySelector('meta[name="theme-color"]').setAttribute('content', '#0d0d0d')
        }
      }
      win.activateLightMode = function () {
        document.documentElement.setAttribute('data-theme', 'light')
        if (document.querySelector('meta[name="theme-color"]') !== null) {
          document.querySelector('meta[name="theme-color"]').setAttribute('content', '#ffffff')
        }
      }
      const t = saveToLocal.get('theme')
    
          if (t === 'dark') activateDarkMode()
          else if (t === 'light') activateLightMode()
        
      const asideStatus = saveToLocal.get('aside-status')
      if (asideStatus !== undefined) {
        if (asideStatus === 'hide') {
          document.documentElement.classList.add('hide-aside')
        } else {
          document.documentElement.classList.remove('hide-aside')
        }
      }
    
    const detectApple = () => {
      if (GLOBAL_CONFIG_SITE.isHome && /iPad|iPhone|iPod|Macintosh/.test(navigator.userAgent)){
        document.documentElement.classList.add('apple')
      }
    }
    detectApple()
    })(window)</script><meta name="generator" content="Hexo 5.4.0"><link rel="alternate" href="/atom.xml" title="Hexo" type="application/atom+xml">
</head><body><div id="sidebar"><div id="menu-mask"></div><div id="sidebar-menus"><div class="avatar-img is-center"><img src="https://i.loli.net/2021/02/24/5O1day2nriDzjSu.png" onerror="onerror=null;src='/img/friend_404.gif'" alt="avatar"/></div><div class="site-data"><div class="data-item is-center"><div class="data-item-link"><a href="/archives/"><div class="headline">Articles</div><div class="length-num">2</div></a></div></div></div><hr/></div></div><div class="post" id="body-wrap"><header class="post-bg" id="page-header" style="background-image: url('https://cdn.jsdelivr.net/npm/butterfly-extsrc@1/img/default.jpg')"><nav id="nav"><span id="blog_name"><a id="site-name" href="/">Hexo</a></span><div id="menus"><div id="toggle-menu"><a class="site-page"><i class="fas fa-bars fa-fw"></i></a></div></div></nav><div id="post-info"><h1 class="post-title">No title</h1><div id="post-meta"><div class="meta-firstline"><span class="post-meta-date"><i class="far fa-calendar-alt fa-fw post-meta-icon"></i><span class="post-meta-label">Created</span><time class="post-meta-date-created" datetime="2021-07-19T14:09:45.390Z" title="Created 2021-07-19 22:09:45">2021-07-19</time><span class="post-meta-separator">|</span><i class="fas fa-history fa-fw post-meta-icon"></i><span class="post-meta-label">Updated</span><time class="post-meta-date-updated" datetime="2021-07-19T14:14:50.827Z" title="Updated 2021-07-19 22:14:50">2021-07-19</time></span></div><div class="meta-secondline"><span class="post-meta-separator">|</span><span class="post-meta-pv-cv" id="" data-flag-title=""><i class="far fa-eye fa-fw post-meta-icon"></i><span class="post-meta-label">Post View:</span><span id="busuanzi_value_page_pv"></span></span></div></div></div></header><main class="layout" id="content-inner"><div id="post"><article class="post-content" id="article-container"><h1 id="一、基础入门—概念名词"><a href="#一、基础入门—概念名词" class="headerlink" title="一、基础入门—概念名词"></a>一、基础入门—概念名词</h1><h2 id="域名"><a href="#域名" class="headerlink" title="域名"></a>域名</h2><blockquote>
<ul>
<li><p>什么是域名？</p>
<ul>
<li><a target="_blank" rel="noopener" href="http://www.xxx.com类似的的网站.(可在万网注册)/">www.xxx.com类似的的网站。（可在万网注册）</a></li>
</ul>
</li>
<li><p>什么是二级域名和多级域名？</p>
<ul>
<li><a target="_blank" rel="noopener" href="http://www.xxx.com中www是顶级域名,xxx是二级域名;/">www.xxx.com中www是顶级域名，xxx是二级域名；</a></li>
</ul>
</li>
</ul>
<p>​                com前面的就是二级域名；</p>
<p>​                xxx前面的是多级域名。</p>
<ul>
<li>域名类型对于安全有什么意义？<ul>
<li>以<a target="_blank" rel="noopener" href="https://www.haut.edu.cn/%EF%BC%88%E6%B2%B3%E5%8D%97%E5%B7%A5%E4%B8%9A%E5%A4%A7%E5%AD%A6%E5%AE%98%E7%BD%91%E4%B8%BA%E4%BE%8B%EF%BC%89%EF%BC%8C%E7%82%B9%E5%BC%80%E9%87%8C%E9%9D%A2%E7%9A%84%E9%80%89%E9%A1%B9%E5%90%8E%E4%BC%9A%E8%B7%B3%E8%BD%AC%E5%88%B0%E5%8F%A6%E4%B8%80%E4%B8%AA%E7%BD%91%E7%AB%99%E4%B8%8A%EF%BC%8C%E5%BD%93%E6%B8%97%E9%80%8F%E4%B8%BB%E7%BD%91%E7%AB%99%E4%B8%8D%E6%88%90%E5%8A%9F%E6%97%B6%EF%BC%8C%E5%8F%AF%E4%BB%A5%E5%B0%9D%E8%AF%95%E5%85%B6%E4%BB%96%E7%9A%84%E5%AD%90%E7%BD%91%E7%AB%99%E8%BF%9B%E8%A1%8C%E6%94%BB%E7%A0%B4%E3%80%82">https://www.haut.edu.cn/（河南工业大学官网为例），点开里面的选项后会跳转到另一个网站上，当渗透主网站不成功时，可以尝试其他的子网站进行攻破。</a></li>
</ul>
</li>
</ul>
</blockquote>
<h2 id="DNS"><a href="#DNS" class="headerlink" title="DNS"></a>DNS</h2><blockquote>
<ul>
<li><p>什么是DNS？    </p>
<ul>
<li>DNS是一个域名系统，是万维网上作为域名和IP地址相互映射的一个分布式数据库，能够使用户更方便的访问互联网，而不用去记住能够被机器直接读取的IP数串。<img src="%E7%AC%94%E8%AE%B0%E5%9B%BE%E7%89%87/1626523962181-d33d83d2-e395-4638-979c-01c91ed49da3.jpeg" alt="屏幕截图 2021-07-17 201217.jpg"></li>
</ul>
</li>
<li><p>如：ping+网站后得到的IP地址【185.199.109.153】就是通过DNS来解析得到的。</p>
</li>
</ul>
<ul>
<li>本地HOSTS与DNS的关系<ul>
<li>在本地hosts文件中加入IP+地址，则ping出来的就是修改后的地址。<img src="%E7%AC%94%E8%AE%B0%E5%9B%BE%E7%89%87/1626524498762-e3b944ab-1125-4c75-8e7c-c8fc6ad83743.png" alt="image.png"></li>
<li>例：如果设置了IP+steam官方网址，则可访问更快。（可用于钓鱼网站）</li>
</ul>
</li>
</ul>
<ul>
<li>CDN是什么？与DNS的关系<ul>
<li>CDN的全称是Content Delivery Network，即<a target="_blank" rel="noopener" href="https://baike.baidu.com/item/%E5%86%85%E5%AE%B9%E5%88%86%E5%8F%91%E7%BD%91%E7%BB%9C/4034265">内容分发网络</a>。CDN是构建在现有网络基础之上的智能虚拟网络，依靠部署在各地的边缘服务器，通过中心平台的负载均衡、内容分发、调度等功能模块，使用户就近获取所需内容，降低网络拥塞，提高用户访问响应速度和命中率。CDN的关键技术主要有内容存储和分发技术。<img src="%E7%AC%94%E8%AE%B0%E5%9B%BE%E7%89%87/1626525037517-11bb730f-5e1c-4dde-b2b9-c10c04a918fb.png" alt="image.png"></li>
<li>我们访问的是节点，服务器在外国，访问的时候只是附近的服务器（看地区）发送的地址。跟DNS无关。</li>
</ul>
</li>
<li>常见的DNS安全攻击有哪些？<ul>
<li>现在常见的DNS攻击，有大流量DOS攻击、基于DNS的漏洞攻击、还有DNS劫持、欺骗等各种攻击方式。</li>
</ul>
</li>
</ul>
</blockquote>
<h2 id="脚本语言"><a href="#脚本语言" class="headerlink" title="脚本语言"></a>脚本语言</h2><blockquote>
<ul>
<li>常见的脚本语言有哪些？<ul>
<li>asp、php、aspx、isp、javaweb、pl、py、cgi等</li>
</ul>
</li>
<li>不同脚本语言类型与安全漏洞的关系？<ul>
<li>安全性的好与差。</li>
</ul>
</li>
<li>漏洞挖掘代码审计与脚本类型的关系？<ul>
<li>后面讲解</li>
</ul>
</li>
</ul>
</blockquote>
<h2 id="后门"><a href="#后门" class="headerlink" title="后门"></a>后门</h2><blockquote>
<ul>
<li>什么后门？有哪些后门？<ul>
<li>侵入一个网站后留下一个后门，方便下次侵入，能控制网站。</li>
</ul>
</li>
<li>后门在安全测试中的实际意义？<ul>
<li>方便下次进入，提供一个“管道”。</li>
</ul>
</li>
<li>关于后门需要了解那些？（玩法，免杀）<ul>
<li>免杀不被设备上的杀毒软件等检查到。</li>
</ul>
</li>
</ul>
</blockquote>
<h2 id="WEB"><a href="#WEB" class="headerlink" title="WEB"></a>WEB</h2><blockquote>
<ul>
<li>WEB的组成框架模型？<ul>
<li>网络源码：分脚本类型，分应用类型</li>
<li>操作系统：Windows，Linux</li>
<li>中间件（搭建平台）：apache、iis、tomcat nginx等</li>
<li>数据库：access、mysql、mssql、oracle、sybase、db2、postsql等</li>
</ul>
</li>
</ul>
</blockquote>
</article><div class="post-copyright"><div class="post-copyright__author"><span class="post-copyright-meta">Author: </span><span class="post-copyright-info"><a href="mailto:undefined">John Doe</a></span></div><div class="post-copyright__type"><span class="post-copyright-meta">Link: </span><span class="post-copyright-info"><a href="http://example.com/2021/07/19/%E5%B0%8F%E8%BF%AAweb%E7%AC%94%E8%AE%B0/">http://example.com/2021/07/19/%E5%B0%8F%E8%BF%AAweb%E7%AC%94%E8%AE%B0/</a></span></div><div class="post-copyright__notice"><span class="post-copyright-meta">Copyright Notice: </span><span class="post-copyright-info">All articles in this blog are licensed under <a target="_blank" rel="noopener" href="https://creativecommons.org/licenses/by-nc-sa/4.0/">CC BY-NC-SA 4.0</a> unless stating additionally.</span></div></div><div class="tag_share"><div class="post-meta__tag-list"></div><div class="post_share"><div class="social-share" data-image="https://cdn.jsdelivr.net/npm/butterfly-extsrc@1/img/default.jpg" data-sites="facebook,twitter,wechat,weibo,qq"></div><link rel="stylesheet" href="https://cdn.jsdelivr.net/npm/social-share.js/dist/css/share.min.css" media="print" onload="this.media='all'"><script src="https://cdn.jsdelivr.net/npm/social-share.js/dist/js/social-share.min.js" defer></script></div></div><nav class="pagination-post" id="pagination"><div class="next-post pull-full"><a href="/2021/07/19/hello-world/"><img class="next-cover" src="https://cdn.jsdelivr.net/npm/butterfly-extsrc@1/img/default.jpg" onerror="onerror=null;src='/img/404.jpg'" alt="cover of next post"><div class="pagination-info"><div class="label">Next Post</div><div class="next_info">Hello World</div></div></a></div></nav></div><div class="aside-content" id="aside-content"><div class="card-widget card-info"><div class="is-center"><div class="avatar-img"><img src="https://i.loli.net/2021/02/24/5O1day2nriDzjSu.png" onerror="this.onerror=null;this.src='/img/friend_404.gif'" alt="avatar"/></div><div class="author-info__name">John Doe</div><div class="author-info__description"></div></div><div class="card-info-data"><div class="card-info-data-item is-center"><a href="/archives/"><div class="headline">Articles</div><div class="length-num">2</div></a></div></div><a class="button--animated" id="card-info-btn" target="_blank" rel="noopener" href="https://github.com/xxxxxx"><i class="fab fa-github"></i><span>Follow Me</span></a></div><div class="card-widget card-announcement"><div class="item-headline"><i class="fas fa-bullhorn card-announcement-animation"></i><span>Announcement</span></div><div class="announcement_content">This is my Blog</div></div><div class="sticky_layout"><div class="card-widget" id="card-toc"><div class="item-headline"><i class="fas fa-stream"></i><span>Catalog</span></div><div class="toc-content"><ol class="toc"><li class="toc-item toc-level-1"><a class="toc-link" href="#%E4%B8%80%E3%80%81%E5%9F%BA%E7%A1%80%E5%85%A5%E9%97%A8%E2%80%94%E6%A6%82%E5%BF%B5%E5%90%8D%E8%AF%8D"><span class="toc-number">1.</span> <span class="toc-text">一、基础入门—概念名词</span></a><ol class="toc-child"><li class="toc-item toc-level-2"><a class="toc-link" href="#%E5%9F%9F%E5%90%8D"><span class="toc-number">1.1.</span> <span class="toc-text">域名</span></a></li><li class="toc-item toc-level-2"><a class="toc-link" href="#DNS"><span class="toc-number">1.2.</span> <span class="toc-text">DNS</span></a></li><li class="toc-item toc-level-2"><a class="toc-link" href="#%E8%84%9A%E6%9C%AC%E8%AF%AD%E8%A8%80"><span class="toc-number">1.3.</span> <span class="toc-text">脚本语言</span></a></li><li class="toc-item toc-level-2"><a class="toc-link" href="#%E5%90%8E%E9%97%A8"><span class="toc-number">1.4.</span> <span class="toc-text">后门</span></a></li><li class="toc-item toc-level-2"><a class="toc-link" href="#WEB"><span class="toc-number">1.5.</span> <span class="toc-text">WEB</span></a></li></ol></li></ol></div></div><div class="card-widget card-recent-post"><div class="item-headline"><i class="fas fa-history"></i><span>Recent Post</span></div><div class="aside-list"><div class="aside-list-item"><a class="thumbnail" href="/2021/07/19/%E5%B0%8F%E8%BF%AAweb%E7%AC%94%E8%AE%B0/" title="No title"><img src="https://cdn.jsdelivr.net/npm/butterfly-extsrc@1/img/default.jpg" onerror="this.onerror=null;this.src='/img/404.jpg'" alt="No title"/></a><div class="content"><a class="title" href="/2021/07/19/%E5%B0%8F%E8%BF%AAweb%E7%AC%94%E8%AE%B0/" title="No title">No title</a><time datetime="2021-07-19T14:09:45.390Z" title="Created 2021-07-19 22:09:45">2021-07-19</time></div></div><div class="aside-list-item"><a class="thumbnail" href="/2021/07/19/hello-world/" title="Hello World"><img src="https://cdn.jsdelivr.net/npm/butterfly-extsrc@1/img/default.jpg" onerror="this.onerror=null;this.src='/img/404.jpg'" alt="Hello World"/></a><div class="content"><a class="title" href="/2021/07/19/hello-world/" title="Hello World">Hello World</a><time datetime="2021-07-19T13:35:44.874Z" title="Created 2021-07-19 21:35:44">2021-07-19</time></div></div></div></div></div></div></main><footer id="footer"><div id="footer-wrap"><div class="copyright">&copy;2020 - 2021 By John Doe</div><div class="framework-info"><span>Framework </span><a target="_blank" rel="noopener" href="https://hexo.io">Hexo</a><span class="footer-separator">|</span><span>Theme </span><a target="_blank" rel="noopener" href="https://github.com/jerryc127/hexo-theme-butterfly">Butterfly</a></div></div></footer></div><div id="rightside"><div id="rightside-config-hide"><button id="readmode" type="button" title="Read Mode"><i class="fas fa-book-open"></i></button><button id="darkmode" type="button" title="Switch Between Light And Dark Mode"><i class="fas fa-adjust"></i></button><button id="hide-aside-btn" type="button" title="Toggle between single-column and double-column"><i class="fas fa-arrows-alt-h"></i></button></div><div id="rightside-config-show"><button id="rightside_config" type="button" title="Setting"><i class="fas fa-cog fa-spin"></i></button><button class="close" id="mobile-toc-button" type="button" title="Table Of Contents"><i class="fas fa-list-ul"></i></button><button id="go-up" type="button" title="Back To Top"><i class="fas fa-arrow-up"></i></button></div></div><div><script src="/js/utils.js"></script><script src="/js/main.js"></script><div class="js-pjax"></div><script async data-pjax src="//busuanzi.ibruce.info/busuanzi/2.3/busuanzi.pure.mini.js"></script></div></body></html>